Malicious PDF — malware analysis report

Static analysis result for SHA-256 050c9a2c4a5943c5…

MALICIOUS

PDF

45.1 KB Authoring application: Scribus
MD5: ca10be2b5379919835d62e648f6e990f SHA-1: 08c0a1dd9039eab3da0d5746009db7692f8d6979 SHA-256: 050c9a2c4a5943c55981c59d974518813fbef29d701330e8c57c3abef68fafd7
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of embedded URLs pointing to other PDF files, a technique often used for SEO spam or to distribute malware. ClamAV detected this as Pdf.Phishing.TtraffRobotInstall-7605656-0, and an ML classifier also flagged it as malicious. The document body contains garbled text but also includes some of the malicious URLs, reinforcing the link farm attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://wallymarket.com/uploads/1/3/0/6/130639766/golatavuk.pdf
    • http://mindfulengagment.com/uploads/1/3/0/7/130738861/zopuxozopo-zexuluna-vazuvoxodes.pdf
    • http://joledac.store/uploads/1/3/0/7/130740174/fisuri.pdf
    • http://phdla.net/uploads/1/3/0/6/130639978/natawoli.pdf
    • http://my-bizco.com/uploads/1/3/0/4/130483385/fa2b8a00.pdf
    • http://untameddemure.com/uploads/1/3/0/6/130621238/3ff32413f3637b.pdf
    • http://awolimited.com/uploads/1/3/0/8/130814923/jozavawokazo-segasodume-tadowowegid.pdf
    • http://rockin-g-resources.com/uploads/1/3/0/2/130289797/mibuv.pdf
    • http://sonsetministries.com/uploads/1/3/0/4/130483400/3197172.pdf
    • http://shardexplorers.com/uploads/1/3/0/3/130313307/130313307.html#hcg+in+blighted+ovum
    • http://linux.thai.net/projects/fonts-tlwg
    • http://www.thaitux.info

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000011c4.bin
716e4c1c8b59826e2615766fd4686e2bf2ef072bba1a2cb4bcd16781ffdb3455
pdf-font-stream PDF embedded font (sfnt) at offset 0x11C4 8152 bytes
font_01_sfnt_off0000687a.bin
c7143368894299a997ed09f05024df052d964886bc902d598de4a6791c50751f
pdf-font-stream PDF embedded font (sfnt) at offset 0x687A 10292 bytes